The flaw entered CISA's catalogue on 5 August. JetBrains' own server was breached through it on the 8th
2026-09-07Security
CVE-2026-63077 is a 9.8 unauthenticated RCE in TeamCity. CISA listed it as actively exploited on 5 August. Three days later, attackers used it against api.cadence.jetbrains.com — JetBrains' own hosted service, running JetBrains' own unpatched product — and left with a 2024 server backup, AWS IAM credentials and users' source code.